Methods and apparatus for providing a secure overlay network between clouds
Summary by NHIP
Secure Cloud Overlay Network
The system establishes a full-mesh secure overlay network by connecting new nodes to all existing nodes via IPSec. An orchestrator creates point-to-point links between interior I/O ports of servers located in distinct private and public clouds.
Claim Score by NHIP
Abstract
A process capable of automatically establishing a secure overlay network (“SON”) across different clouds is disclosed. The process, in one aspect, receives a first request from a first node in a first cloud for establishing a SON. After receiving a second request for connecting to the SON from a second node in a second cloud, a first connection is established connecting between the first node and the second node utilizing a network security protocol such as Internet Protocol Security (“IPSec”). After receiving a third request for connecting to the SON from a third node in a third cloud, a second connection is used to connect between the first node and the third node. A third connection is used to connect between the second node and the third node. Each subsequent request for connecting to the SON from a new node results in new connections between the new node and each existing node in the SON forming a full-mesh.

Term
8.2 yearsleft in the term
Expires 5 December 2034.
- Priority and filed
- Granted
- Today
- Expires
14 claims: 2 independent, 12 dependent
- 1Broadest claimClaim Score 22, narrow(NHIP)A communication network having a plurality of virtual machines (“VMs”), comprising:a first private cloud configured to provide network services to a plurality of users, the first private cloud comprising a first edge input and output (“I/O”) port into and out of the first private cloud, the first private cloud further comprising a first server inside the first private cloud, the first server having a first interior I/O port;a public cloud configured to provide cloud computing service to users, the public cloud comprising a second edge I/O port into and out of the public cloud, the public cloud further comprising a second server inside the public cloud, the second server having a second interior I/O port;a communications network connecting the first edge I/O port of the first private cloud to the second edge I/O port of the public cloud;an orchestrator coupled to the first private cloud and the public cloud, wherein the orchestrator is configured to establish a first point-to-point connection laid over the communications network for logically direct communication between the first interior I/O port of the first server inside the first private cloud and the second interior I/O port of the second server inside the public cloud in accordance with a network security protocol, wherein the orchestrator comprises a computer processor;and a second private cloud coupled to the first private cloud and configured to provide network services to a plurality of users, wherein the orchestrator is configured to generate a second point-to-point connection between a first I/O port of the first server and a third I/O port of a third server in the second private cloud, wherein the orchestrator is configured to generate a third point-to-point connection between a second I/O port of the second server in the public cloud and the third I/O port of the third server in the second private cloud.
- 10A method for generating network connections between cloud computing managed by an orchestrator, comprising:presenting a dashboard including an option of creating a secure overlay network (“SON”) to a user by the orchestrator via a communication network, wherein the orchestrator comprises a computer processor;receiving over the communication network a first selection requesting a first SON for a point-to-point connection from a first interior input and output (“I/O”) port of a first virtual server inside a first cloud;receiving over the communication network a second selection requesting the first SON and a second SON from a second interior I/O port of a second virtual server inside a second cloud;establishing a first point-to-point logically direct connection laid over an existing network between the first interior I/O port of the first virtual server and the second interior I/O port of the second virtual server in accordance with the first SON utilizing a network security protocol, wherein the existing network connects a first edge I/O port of the first cloud to a second edge I/O port of the second cloud;receiving a third selection requesting the second SON from a third virtual server in a third cloud and establishing a second point-to-point connection between the second virtual server in the second cloud and the third virtual server in the third cloud in accordance with the second SON utilizing Internet Protocol Security (“IPsec”);and receiving a fourth selection requesting the first SON and the second SON from a fourth virtual server in a fourth cloud and establishing a third point-to-point connection between the fourth virtual server in the fourth cloud and the third virtual server in the third cloud in accordance with the second SON utilizing Internet Protocol Security (“IPsec”).
Independent claims2
74 paragraphs in 5 sections, as filed
FIELD
0001The exemplary embodiment(s) of the present invention relates to communication networks. More specifically, the disclosed embodiment(s) of the present application relates to communication between clouds.
BACKGROUND
0002In today's modern computing world, more and more components are being virtualized to save capital expenditure for various entities, such as companies, public institutions, government agencies, individuals, and the like. To further reduce expenditure and conserve resources, entities are gradually allowing third party providers to maintain cloud infrastructure for hosting subscribers' virtual as well as physical components. A cloud or cloud provider, also known as cloud computing or a cluster of servers, becomes viable when entities need to increase their computing capacity or new features without investing in substantial amount of new infrastructure, personnel, hardware and/or software. It should be noted that typical third party or public cloud infrastructure providers includes, but not limited to, Amazon™, Google™, RackSpace™, and the like. For example, a cloud provider supplies cloud computing which can be subscription-based or pay-per-use service accessible over the Internet.
0003While some components or devices can be virtualized, others are still physical machines with hardware components placed in the vicinity of premise(s), such as laboratories, testing sites, demo sites, manufacturing facilities, and so forth. However, a problem associated with devices and/or components situated in various clouds is that a seamless communication between such components located in different clouds is difficult to achieve. A conventional approach to resolve this problem typically requires cumbersome information technology (“IT”) steps requiring skilled IT administrator(s) to setup each direct connection. For example, the steps may require a skilled IT person to setup communication between devices located in different cloud locations. The manual steps may involve in opening firewalls for certain private clouds and additional scripts may be needed to setup certain connections or links.
SUMMARY
0004A secure overlay network (“SON”), in one embodiment, can be automatically established to enhance device communication between different clouds located in different locations. For example, a process able to create an overlay network receives a first request from a dashboard managed by an orchestrator for establishing a SON. SON is capable of facilitating a point-to-point connection between nodes residing in different clouds. A node can be a cluster of network devices or components, such as routers, hosts, switches, servers, database, and the like. After receiving a second request for connecting to the SON from a second node of a second cloud, a first connection is established between the first node and the second node using network security protocol such as Internet Protocol Security (“IPSec”). After receiving a third request for connecting to the SON from a third node in a third cloud, a second connection is established to connect the first node to the third node. A third connection is created to connect the second node to the third node.
0005Additional features and benefits of the exemplary embodiment(s) of the present invention will become apparent from the detailed description, figures and claims set forth below.
BRIEF DESCRIPTION OF THE DRAWINGS
The exemplary embodiment(s) of the present invention will be understood more fully from the detailed description given below and from the accompanying drawings of various embodiments of the invention, which, however, should not be taken to limit the invention to the specific embodiments, but are for explanation and understanding only.
<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram illustrating a network having an orchestrator able to manage and launch a secure overlay network (“SON”) between clouds in accordance with one embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram illustrating an exemplary orchestrator having a dashboard capable of managing a SON in accordance with one embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram illustrating an exemplary dashboard able to facilitate launch and manage a SON in accordance with one embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 4</figref> is a block logic diagram illustrating exemplary clouds connected by a SON in accordance with one embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 5</figref> is a block diagram illustrating an exemplary network configuration having multiple clouds coupled with a SON in accordance with one embodiment of the present invention;
<figref idref="DRAWINGS">FIG. 6</figref> is a logic block diagram illustrating an exemplary process of establishing a SON across cloud boundaries in accordance with one embodiment of the present invention; and
<figref idref="DRAWINGS">FIG. 7</figref> is a flowchart illustrating an exemplary process of establishing a SON coupling multiple clouds together in accordance with one embodiment of the present invention.
DETAILED DESCRIPTION
0014Exemplary embodiment(s) of the present invention is described herein in the context of a method, device, and apparatus for establishing and managing a secure overlay network (“SON”) over a virtual network (“VN”) containing multiple clouds.
0015Those of ordinary skills in the art will realize that the following detailed description of the exemplary embodiment(s) is illustrative only and is not intended to be in any way limiting. Other embodiments will readily suggest themselves to such skilled persons having the benefit of this disclosure. Reference will now be made in detail to implementations of the exemplary embodiment(s) as illustrated in the accompanying drawings. The same reference indicators will be used throughout the drawings and the following detailed description to refer to the same or like parts.
0016In the interest of clarity, not all of the routine features of the implementations described herein are shown and described. It will, of course, be understood that in the development of any such actual implementation, numerous implementation-specific decisions may be made in order to achieve the developer's specific goals, such as compliance with application- and business-related constraints, and that these specific goals will vary from one implementation to another and from one developer to another. Moreover, it will be understood that such a development effort might be complex and time-consuming, but would nevertheless be a routine undertaking of engineering for those of ordinary skills in the art having the benefit of embodiment(s) of this disclosure.
0017Various embodiments of the present invention illustrated in the drawings may not be drawn to scale. Rather, the dimensions of the various features may be expanded or reduced for clarity. In addition, some of the drawings may be simplified for clarity. Thus, the drawings may not depict all of the components of a given apparatus (e.g., device) or method.
0018Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skills in the art to which the exemplary embodiment(s) belongs. It will be further understood that terms, such as those defined in commonly used dictionaries, should be interpreted as having a meaning that is consistent with their meaning in the context of the relevant art and this exemplary embodiment(s) of the disclosure.
0019As used herein, the singular forms “a”, “an” and “the” are intended to include the plural forms as well, unless the context clearly indicates otherwise. It will be further understood that the terms “comprises” and/or “comprising,” when used in this specification, specify the presence of stated features, integers, steps, operations, elements, and/or components, but do not preclude the presence or addition of one or more other features, integers, steps, operations, elements, components, and/or groups thereof. The term “and/or” includes any and all combinations of one or more of the associated listed items.
0020The term “system” is used generically herein to describe any number of components, elements, sub-systems, devices, packet switch elements, packet switches, access switches, routers, networks, computer and/or communication devices or mechanisms, or combinations of components thereof. The term “computer” includes a processor, memory, and buses capable of executing instruction wherein the computer refers to one or a cluster of computers, personal computers, workstations, mainframes, or combinations of computers thereof.
0021IP communication network, IP network, or communication network means any type of network having an access network able to transmit data in the form of packets or cells, such as ATM (Asynchronous Transfer Mode) type, on a transport medium, for example, the TCP/IP or UDP/IP type. ATM cells are the result of decomposition (or segmentation) of packets of data, IP type, and those packets (here IP packets) comprise an IP header, a header specific to the transport medium (for example UDP or TCP) and payload data. The IP network may also include a satellite network, a DVB-RCS (Digital Video Broadcasting-Return Channel System) network, providing Internet access via satellite, or an SDMB (Satellite Digital Multimedia Broadcast) network, a terrestrial network, a cable (xDSL) network or a mobile or cellular network (GPRS/EDGE, or UMTS (where applicable of the MBMS (Multimedia Broadcast/Multicast Services) type, or the evolution of the UMTS known as LTE (Long Term Evolution), or DVB-H (Digital Video Broadcasting-Handhelds)), or a hybrid (satellite and terrestrial) network.
0022One embodiment of the present application discloses a mechanism creating a SON to provide point-to-point connections between various nodes or hosts situated in different clouds. The mechanism or process, in one aspect, is able to receive a first request from a dashboard requesting a SON. Note that the SON is capable of facilitating a point-to-point connection between nodes residing in different clouds. A node can be a cluster of network devices or components, such as routers, hosts, switches, servers, database, and the like.
0023After receiving a second request for connecting to the SON from a second node of a second cloud, a first connection is established between the first node in first cloud and the second node in second cloud using network security protocol such as IPSec. After receiving a third request to connect to the SON from a third node in a third cloud, a second connection is created to connect the first node in first cloud to the third node in third cloud. Similarly, a third connection is built to connect the second node in second cloud to the third node in third cloud. It should be noted that the connections could be logical point-to-point connections.
0024<figref idref="DRAWINGS">FIG. 1</figref> is a block diagram <b>100</b> illustrating a network having an orchestrator able to manage and launch a SON between clouds in accordance with one embodiment of the present invention. Diagram <b>100</b> includes network or clouds <b>102</b>-<b>104</b>, private cloud <b>106</b>, and public cloud <b>108</b>. Note that the terms “network” and “cloud” can be used interchangeably to indicate a group of hardware and/or software devices connected with each other to perform a networking function(s). Cloud <b>104</b>, which can be either a private cloud or public cloud, contains or hosts orchestrator <b>112</b>. Orchestrator <b>112</b>, in one aspect, is coupled to various users <b>124</b>-<b>130</b> via one or more clouds and/or networks such as cloud <b>102</b>. It should be noted that the underlying concept of the exemplary embodiment(s) of the present invention would not change if one or more blocks (or devices) were added to or removed from diagram <b>100</b>.
0025A cloud is cloud computing which includes a cluster of servers residing in the cloud. The servers in the cloud are able to support or host multiple virtual machines (“VMs”) running simultaneously. Cloud computing basically uses various resources including hardware, firmware, and software to deliver computing service. A benefit of using a cloud is that it shares resources with other users so that resources can be used more efficiently. Another benefit of using a cloud is that it is able to dynamically reallocate resources on demand.
0026A cloud can be a private cloud, a public cloud, or a hybrid cloud. A private cloud such as cloud <b>106</b> is operated for a purpose of an individual corporation, organization, and/or entity. The private cloud, in one example, can provide cloud-computing services over a network. Note that a private cloud can be managed or hosted internally, externally, or both. Cloud <b>106</b>, for example, includes a set of servers <b>114</b> capable of virtualizing various assigned operations using a group of VMs <b>116</b>.
0027A public cloud such as enterprise public cloud <b>108</b> that is open to the public providing computing services over a communication network. A public cloud, which is also known as community cloud, can be free or based on a fee schedule in exchange of clouding service. For example, exemplary public cloud service providers can be Amazon web services (AWS)™, Microsoft™, Apple™, and/or Google™ and are able to host services across the Internet. Enterprise public cloud <b>108</b>, in one example, includes an array of servers capable of hosting and supporting a set of VMs <b>118</b> running simultaneously.
0028Hybrid cloud, in one example, is a combination of multiple clouds including private and public clouds. In an alternative example, a hybrid cloud includes VMs as well as physical machines in one or more clouds. Hybrid cloud is able to host or support a set of VMs as well as physical machines operating simultaneously.
0029One advantage of using a cloud operating multiple VMs instead of hardware is that some or a portion of traditional dedicated hardware devices such as routers and switches may not be required to build a network. Alternatively, a cloud can also combine VMs with existing hardware devices to optimize the performance of VN.
0030Orchestrator <b>112</b>, in one aspect, arranges, coordinates, and manages one or more VNs based on users' requests. In addition to virtualization, orchestrator <b>112</b> is able to provide other network related functions, such as provisioning, workflows, flexible resource allocation, billing, metering, accounting, policies, and user interfaces. To improve network performance, orchestrator <b>112</b>, in one embodiment, is able to scale up or scale down based on demand based on the performance of VN. The terms “orchestrator,” “network orchestrator,” and “orchestrator of network,” mean the same apparatus and they can be used interchangeably.
0031A VM is a software implementation of a particular computer system that processes tasks like a real physical machine. For instance, VM can be configured to execute instructions in a way that follows the emulated computer architecture. A server or a cluster of servers containing specialized hardware and software may be used to provide a VM environment that allows multiple VMs to be operated simultaneously. VM includes system virtual machines and process virtual machines. The system virtual machine includes a set of functions operating based on an operating system. The process virtual machine is able to execute a program based on platform-independent program execution environment. Instance means a VM configured to execute program based on the emulation of a real machine or apparatus.
0032Private cloud or private network cloud <b>106</b> provides network services to a group of remote users across a network. In one aspect, private network cloud <b>106</b> is configured to contain a group of servers <b>114</b> capable of supporting multiple VMs <b>116</b> running at the same or substantially the same time. To communicate with orchestrator <b>112</b>, private cloud <b>106</b> uses at least one Engreen™ host manager (“ehm”) <b>117</b> which can be placed in one of servers <b>114</b> to communicate with orchestrator <b>112</b>.
0033Public network cloud or enterprise public cloud <b>108</b>, which is coupled to private network cloud <b>106</b> via orchestrator <b>112</b>, is configured to provide cloud-computing service to remote users based on applications. Based on a requested or desired or constructed VN, a public network cloud <b>108</b> may be selected or chosen to host the requested VN. The requested VN is subsequently launched in public network cloud <b>108</b>. Public network cloud <b>108</b> is able to host and execute VN(s) using various VMs <b>118</b> based on the input from user, orchestrator, or both. To communicate with orchestrator <b>112</b>, public network cloud <b>108</b> uses a cloud application-programming interface (“API”) <b>122</b> to facilitate communication between orchestrator <b>112</b> and public cloud <b>108</b>. A cloud API or APIs, in one example, facilitate establishing VNs.
0034Orchestrator <b>112</b>, in one embodiment, communicates with users <b>128</b>-<b>130</b> coupled to orchestrator <b>112</b> directly via cloud <b>104</b> and users <b>124</b>-<b>126</b> coupled to orchestrator <b>112</b> via a cloud <b>102</b>. Some users such as user <b>124</b> are connected to orchestrator <b>112</b> via a wireless network. Orchestrator <b>112</b> is able to manage VMs <b>116</b>-<b>118</b> located in clouds <b>106</b>-<b>108</b> in response to input from remote users such as user <b>124</b> or user <b>130</b>.
0035Orchestrator <b>112</b>, in one embodiment, includes multiple dashboards, not shown in <figref idref="DRAWINGS">FIG. 1</figref>, wherein the dashboards are used to communicate with subscribers or users <b>124</b>-<b>130</b> via one or more networks. For example, orchestrator <b>112</b> is able to post a set of icons on the dashboards to facilitate user input. The icons, in one embodiment, are templates representing virtual components and/or real network devices. With input from one or more subscribers or users <b>124</b>-<b>130</b>, orchestrator <b>112</b> is able to assist a subscriber to establish a VN based on selected templates via dashboard(s). It should be noted that additional private clouds and/or public clouds may be added in diagram <b>100</b>. For example, multiple clouds containing different sets of VMs and physical machines may be selected by orchestrator to launch a selected VN. One advantage of using an orchestrator to manage VNs is that the orchestrator may allow a predefined group of subscribes to clone an established VN.
0036To facilitate point-to-point connections between components situated in different clouds, a SON such as SON <b>132</b> can be established. SON <b>132</b>, in one embodiment, is an overlay network capable to provide direct connection between server <b>114</b> in cloud <b>106</b> and VM <b>118</b> in cloud <b>108</b>. In one aspect, SON <b>132</b> is created based on a network security protocol such as IPSec overlaying an existing Internet link. For example, SON <b>132</b> is established over the existing network between links <b>136</b>-<b>138</b> and cloud <b>104</b>. A function of SON <b>132</b> is to cause two connected end devices as they are logically direct-connected.
0037An overlay network can be considered as a communication network or a computer network that is established on the top of another network. Nodes in the overlay network are considered as being connected by virtual or logical links. Each virtual or logic link may correspond to a path that may travel through multiple physical connections through the physical or underlying network. In one embodiment, a SON is based on the overlay network that resides on top of another existing network such as the Internet.
0038A virtual appliance is a predefined VM and is able to run on a virtual machine monitor or platform such as a hypervisor. A hypervisor is a combination of computer software, firmware or hardware that is able to host and run VMs. For example, a virtual appliance allows a user to run virtual applications without installation and/or configuration of the virtual machine platform. An advantage of sharing a template of VN is that it allows a group of users to work on a similar network for the same as well as different tasks.
0039To create a seamless SON, a user can select a SON icon on a dashboard managed by orchestrator <b>112</b>. The SON icon provides an option to a user before a VN is instantiated via the virtual network management (“VNM”) framework. Once SON <b>132</b> is created, servers that have been added to the service as compute nodes can be added to SON <b>132</b>. After the initial setup, SON <b>132</b> is available for selection as a communications channel between clouds. When SON connects to two or more network components, orchestrator <b>112</b> automatically sets up the secure overlay network such that the network instances can communicate with each other as if they are directly connected. It should be noted that SON is applicable between public and private clouds <b>106</b>-<b>108</b>, public and public clouds (e.g., Amazon & Rackspace), or private and private clouds (e.g., two (2) different corporate datacenters located in different locations).
0040An advantage of using SON is that orchestrator allows users to launch a SON for facilitating communication between clouds without intervention from administrator, firewall changes, manual configuration, and the like. It should be noted that automation of SON launch conserves resources such as manual operation and human interaction whereby the SON enhances overall network performance.
0041<figref idref="DRAWINGS">FIG. 2</figref> is a block diagram illustrating an exemplary orchestrator having a dashboard capable of managing SON in accordance with one embodiment of the present invention. Diagram <b>200</b> shows a network including an enterprise private cloud <b>202</b>, orchestrator <b>204</b>, and dashboard <b>212</b>. Dashboard <b>212</b>, in one aspect, resides online which can be accessed via a browser <b>206</b>. A physical machine such as system <b>220</b>, in one example, can be coupled to cloud <b>202</b> as part of cloud <b>202</b>. It should be noted that the underlying concept of the exemplary embodiment(s) of the present invention would not change if one or more blocks (or devices) were added to or removed from diagram <b>200</b>.
0042Orchestrator <b>204</b>, in one embodiment, includes an application server <b>214</b>, web server <b>216</b>, database <b>218</b>, and SON manager <b>230</b>. Orchestrator <b>204</b> may be hosted by a private, public, micro, or hybrid cloud. In one example, orchestrator <b>204</b> can be hosted by cloud <b>202</b>. Alternatively, another private or public cloud may be used to host orchestrator <b>204</b>. Application server <b>214</b> is used to communicate with enterprise cloud <b>202</b> via network connection <b>224</b>. Connection <b>224</b> can be a wired, wireless, or a combination of wired and wireless network connection. A function of application server <b>214</b> is to remotely control or manage VN(s) and/or SON(s) running at cloud <b>202</b> via ehm <b>210</b>. Ehm <b>210</b>, which may be residing in one or multiple servers <b>208</b>, is able to report VN status to application server <b>214</b> and receives instruction(s) from application server <b>214</b>.
0043Web server <b>216</b>, in one embodiment, is used to communicate with user(s) or subscriber(s) via dashboard(s) <b>212</b>. In one aspect, Web server <b>216</b> is capable of selectively posting icons or templates on dashboard(s) via a wired or wireless connection <b>226</b>. When a user or subscriber logs into orchestrator <b>204</b> via a web browser such as browser <b>206</b>, dashboard <b>212</b> will display various predefined icon images including a SON option. A function of dashboard <b>212</b> is that it allows a subscriber to pick and choose virtual devices represented by the icons to build a unique or application specific VN. Alternatively, dashboard <b>212</b> may also offer an opportunity for a user or subscriber to clone an existing VN.
0044SON manager <b>230</b>, which can be hardware, software, firmware, or a combination of hardware, software, and firmware, is configured to facilitate launching and maintaining an overlay network for network communication. For example, SON manager <b>230</b> may include a SON table, not shown in <figref idref="DRAWINGS">FIG. 2</figref>, wherein the table records or maps one or more overlay networks. Depending on the applications, an active SON may be created based on secure, automatic, and/or dynamically overlaying across multiple clouds via an existing communication network. Clouds, for instance, can be located at different geographical locations. A function of SON manager <b>230</b> is to provide a method or procedure to dynamically create and manage one or more SONs over one or more existing networks across several clouds.
0045Orchestrator <b>204</b>, which can also be referred to as network orchestrator, network manager, and/or orchestrator of networks, is able to manage virtual devices as well as physical devices. Orchestrator <b>204</b> can also provide automatic scaling in response to the demand and/or execution of VN(s). An advantage of using an orchestrator is that it provides automatic convergence as well as leveraging resources in different physical locations.
0046Cloud <b>202</b> is similar to cloud <b>106</b>, shown in <figref idref="DRAWINGS">FIG. 1</figref>, except that cloud <b>202</b> is coupled to physical machine <b>220</b>. In one example, cloud <b>202</b> is a private cloud operated by an entity. The entity builds a unique VN to test its network device that may be installed in physical machine <b>220</b>. After a provisioning process, orchestrator <b>204</b> facilitates building a requested VN that integrates physical machine <b>220</b> as a part of VN in accordance with the subscriber's request. Once a desirable SON is built or established, other components are allowed to join in the SON once such components are verified and authenticated.
0047An advantage of providing a SON option by dashboard <b>212</b> is that it allows other users or subscribers to automatically launch or join SON without cumbersome process and administrators' interaction.
0048<figref idref="DRAWINGS">FIG. 3</figref> is a block diagram <b>300</b> illustrating an exemplary dashboard able to facilitate launch and manage SON in accordance with one embodiment of the present invention. Diagram <b>300</b> includes clouds <b>102</b>-<b>108</b>, orchestrator <b>112</b>, and dashboard <b>308</b>. Dashboard <b>308</b>, in one embodiment, includes a toolbar <b>306</b>, template <b>302</b>, and pull-down menu <b>304</b>. Toolbar <b>306</b> lists various buttons representing various functions such as home button and template <b>302</b>. It should be noted that the underlying concept of the exemplary embodiment(s) of the present invention would not change if one or more blocks (or devices) were added to or removed from diagram <b>300</b>.
0049Pull-down menu <b>304</b> illustrates multiple icons <b>310</b>-<b>322</b> representing various virtual or real network related devices (or components) when template <b>302</b>, for example, is clicked. Menu <b>304</b> lists various icons, such as tower <b>310</b>, router <b>312</b>, rack <b>314</b>, network device <b>316</b>, cloud <b>318</b>, connection <b>320</b>, and/or SON option <b>322</b>. SON option <b>322</b> can also be configured as a button or icon as tower <b>310</b> or router <b>312</b>. A subscriber or user can selectively pick and choose any icons to build a desirable virtual network. Once a set of icons is selected, orchestrator will select one of clouds <b>102</b>-<b>108</b> to launch the selected VN. Depending on the applications, orchestrator <b>112</b> may scale up or down depending on the demand of computing power in accordance with the selected VN.
0050An advantage of providing SON option on dashboard <b>308</b> is that it allows a user to select SON option before the launch of a desirable VN.
0051<figref idref="DRAWINGS">FIG. 4</figref> is a block diagram <b>400</b> illustrating exemplary clouds connected via a SON in accordance with one embodiment of the present invention. Diagram <b>400</b> includes orchestrator <b>204</b> and two private clouds <b>402</b>-<b>404</b> which are interconnected via a virtual private network (“VPN”) <b>408</b>. VPN <b>408</b>, in one example, can be a private network, public network, or a combination of public and private network. It should be noted that the underlying concept of the exemplary embodiment(s) of the present invention would not change if one or more blocks (or devices) were added to or removed from diagram <b>400</b>.
0052VPN <b>408</b> is capable of transporting data between clouds <b>402</b>-<b>404</b> using links and/or channels <b>406</b>. VPN <b>408</b> may include one or more networks such as the Internet and/or wide area network (“WAN”) to provide network communications. VPN, in one instance, includes proxy servers to cover and to improve network services. In one embodiment, SON <b>480</b> is established over VPN <b>408</b> providing point-to-point connection between node <b>409</b> and node <b>440</b>. A node, in one example, includes server(s), VM(s), physical network device(s), or a cluster of physical devices and VMs.
0053Cloud <b>402</b> includes multiple functional blocks or nodes such as servers <b>409</b>-<b>411</b> wherein server <b>409</b> is further connected to router <b>412</b>, database <b>416</b>, and controller <b>418</b>. Similarly, while server <b>410</b> is connected to router <b>422</b>, database <b>426</b>, and controller <b>428</b>, server <b>411</b> is coupled to router <b>432</b>, database <b>436</b>, and controller <b>438</b>. Alternatively, cloud <b>402</b> can be configured to include routers <b>409</b>-<b>411</b> wherein each router is able to launch and maintain multiple VMs. For example, router <b>409</b> maintains VM <b>412</b> as virtual server, VM <b>416</b> as virtual database, and VM <b>418</b> as virtual controller.
0054It should be noted that routers, databases, servers, and/or controllers can be virtual machines, physical machines, and/or a combination of virtual machines and physical machines. Cloud <b>402</b>, for example, may contain additional components, such as routers, switches, hubs, servers, databases, and the like. Depending on the applications, components or devices such as routers and servers can be dynamically added or removed on demand.
0055Servers <b>409</b>-<b>411</b> are interconnected by a set of internal links <b>472</b>. In one example, internal network <b>470</b> couples an edge I/O (input and output) port <b>476</b> of cloud <b>402</b> to nodes <b>409</b>-<b>411</b>. Internal network <b>470</b>, in one example, encompasses a cluster of links <b>472</b> used for connections. It should be noted that internal links <b>472</b> and network <b>470</b> could be virtual, physical, or a combination of virtual and physical connections.
0056Cloud <b>404</b>, which is similar to cloud <b>402</b>, includes multiple functional blocks or nodes such as servers <b>439</b>-<b>441</b> wherein server <b>439</b> is connected to router <b>442</b>, database <b>446</b>, and/or controller <b>448</b>. Server <b>440</b> is connected to router <b>452</b>, database <b>456</b>, and controller <b>458</b>. Server <b>441</b> is coupled to router <b>462</b>, database <b>466</b>, and controller <b>468</b>. In an alternative embodiment, cloud <b>404</b> is configured to include servers <b>439</b>-<b>441</b> wherein each server is able to manage multiple VMs. For example, server <b>439</b> maintains VM <b>442</b> as virtual server, VM <b>446</b> as virtual database, and VM <b>418</b> as virtual controller.
0057Servers <b>439</b>-<b>441</b> are interconnected by a set of internal links <b>473</b>. In one example, an internal network <b>471</b> is used to facilitate connections between links <b>473</b> with edge I/O port <b>478</b> of cloud <b>404</b>. It should be noted that internal links <b>473</b> and network <b>471</b> can be virtual, physical, or a combination of virtual and physical connections.
0058In one embodiment, the communication network illustrated by diagram <b>400</b> shows a SON <b>480</b> configured to provide point-to-point connection between node <b>409</b> and node <b>440</b>. While nodes <b>409</b>-<b>411</b> reside in cloud <b>402</b> and nodes <b>439</b>-<b>441</b> reside in cloud <b>404</b>, SON <b>480</b> is established over existing VPN <b>408</b>. In one aspect, orchestrator <b>204</b> is used to control and maintain SON <b>480</b>.
0059Orchestrator <b>204</b>, which is coupled to clouds <b>402</b>-<b>404</b>, is able to establish a point-to-point connection between the I/O port of a first server in cloud <b>402</b> and I/O port of a second server in cloud <b>404</b> in accordance with a network security protocol. In one embodiment, the network security protocol is IPSec that is capable of building point-to-point connections based on an existing network.
0060Diagram <b>400</b> may further include a third private cloud, not shown in <figref idref="DRAWINGS">FIG. 4</figref>, configured to provide network services to users. Orchestrator <b>204</b> is able to generate a second point-to-point connection between the I/O port of the first server in cloud <b>402</b> and an I/O port of a third server in the third private cloud. To provide a SON, orchestrator <b>204</b> is able to generate a second point-to-point connection between the second I/O port of the second server in cloud <b>404</b> and the third I/O port of the third server in the third private cloud as well as a third point-to-point connection between the first I/O port of the first server in cloud <b>402</b> and third I/O port of the third server in the third private cloud. Orchestrator <b>204</b> is able to implement SON <b>480</b> over an existing network or VPN <b>408</b> to establish point-to-point connections in accordance with IPSec.
0061An advantage of using SON is that SON allows a user to test a desirable network that could span across one or more cloud boundaries. For example, various virtual and physical devices located in different locations can be connected using a secure and automated overlay network. SON, in one embodiment, allows the secure and seamless communication between the devices using point-to-point (or end-to-end) connections (or links). It should be noted that an overlay network can be created automatically when the network is launched. Orchestrator <b>112</b> is also capable of tearing or terminating an existing SON when it is no longer needed.
0062<figref idref="DRAWINGS">FIG. 5</figref> is a block diagram <b>500</b> illustrating an exemplary network configuration having multiple clouds coupled with SON in accordance with one embodiment of the present invention. Diagram <b>500</b> includes clouds <b>502</b>-<b>508</b>, orchestrator <b>112</b>, and VPN <b>408</b>, wherein clouds <b>502</b>-<b>508</b> are situated in geographically different locations. For example, cloud <b>502</b> may be in San Jose and cloud <b>504</b> is in Bangalore. While cloud <b>508</b> is in Beijing, cloud <b>506</b> is an Amazon™ public cloud situated in Seattle. Clouds <b>502</b>-<b>508</b> are connected by VPN <b>408</b> via channels <b>552</b>-<b>558</b> through edge I/O ports <b>572</b>-<b>578</b>. It should be noted that the underlying concept of the exemplary embodiment(s) of the present invention would not change if one or more blocks (or devices) were added to or removed from diagram <b>500</b>.
0063Cloud <b>502</b> includes multiple nodes such as nodes or servers <b>530</b>-<b>534</b> wherein each node further includes one or more VMs, physical devices, and/or a combination of VM and physical device. For example, node <b>530</b>, which can be a server, host, switch, hub, et cetera, includes multiple components <b>536</b> connected by a set of internal links <b>537</b>. Similarly, Cloud <b>504</b> includes nodes or servers <b>540</b>-<b>544</b> wherein each node further includes one or more VMs, physical devices, and/or a combination of VM and physical device. For example, node <b>540</b>, which can be a server, host, switch, hub, et cetera, includes multiple components <b>546</b> connected by a set of internal links <b>547</b>.
0064Also, cloud <b>506</b> includes nodes or servers <b>510</b>-<b>514</b> wherein each node further includes one or more VMs, physical devices, and/or a combination of VM and physical device. For example, node <b>510</b>, which can be a server, host, switch, hub, et cetera, includes multiple components <b>516</b> connected by a set of internal links <b>517</b>. Similarly, Cloud <b>508</b> includes nodes <b>520</b>-<b>524</b> wherein each node may further includes one or more VMs, physical devices, and/or a combination of VM and physical device. For example, node <b>520</b>, which can be a server, host, switch, hub, et cetera, includes multiple components <b>526</b> connected by a set of internal links <b>527</b>.
0065A communication network or VPN <b>408</b> is used to link clouds <b>502</b>-<b>508</b> together via connections <b>552</b>-<b>558</b>. Connections <b>552</b>-<b>558</b> are employed to link I/O ports <b>572</b>-<b>578</b> of clouds <b>502</b>-<b>508</b> for information transmission. In one embodiment, a SON is established over VPN <b>408</b> to provide point-to-point connections. For example, I/O port <b>538</b> of node <b>530</b> can be connected to I/O port <b>548</b> of node <b>540</b> using point-to-point connections <b>564</b>-<b>566</b> established over existing VPN <b>408</b> using SON. Similarly, I/O port <b>538</b> of node <b>530</b> can be connected to I/O port <b>518</b> of node <b>510</b> using point-to-point connections <b>564</b> and <b>562</b> established over existing VPN <b>408</b> using SON. Also, I/O port <b>528</b> of node <b>520</b> can be connected to I/O port <b>548</b> of node <b>540</b> and I/O port <b>538</b> of node <b>530</b> wherein point-to-point connections <b>566</b>-<b>568</b> are used to link between ports <b>528</b> and <b>548</b>, and point-to-point connection <b>564</b> and <b>568</b> are used to link between ports <b>528</b> and <b>538</b> of node <b>530</b>.
0066In one embodiment, orchestrator <b>112</b> is able to communication with nodes directly using links <b>560</b> to facilitate building a SON. A network security protocol may be used to build an overlay network over an existing network. In one embodiment, the network security protocol is IPSec. When SON is established, a full-mesh connection between selected nodes is generated.
0067During an exemplary operation, orchestrator <b>112</b> is able to present a dashboard via a communication network to a user or subscriber wherein the dashboard displays an option of creating a SON. A first selection requesting SON such as SON <b>570</b> is received for point-to-point connections from a first virtual server <b>530</b> in a first cloud <b>502</b> over the communication network <b>408</b>. After receiving a second selection requesting SON <b>570</b> from a second virtual server <b>540</b> in a second cloud <b>504</b> over the communication network such as VPN <b>408</b>, a first point-to-point connection <b>564</b>-<b>566</b> between first virtual server <b>530</b> and second virtual server <b>540</b> is established in accordance with SON <b>570</b> using a network security protocol such as IPSec. After receiving a third selection requesting SON <b>570</b> from a third virtual server <b>520</b> in a third cloud <b>508</b>, a second point-to-point connection <b>566</b>-<b>568</b> between second virtual server <b>540</b> in second cloud <b>504</b> and third virtual server <b>520</b> in third cloud <b>508</b> as well as a third point-to-point connection <b>564</b>-<b>568</b> between first virtual server <b>530</b> in first cloud <b>502</b> and third virtual server <b>520</b> in third cloud <b>508</b> are established in accordance with SON <b>570</b>.
0068Upon establishing SON <b>570</b> using point-to-point connections <b>562</b>-<b>568</b> connecting nodes <b>510</b>-<b>540</b>, a full-mesh network is generated. An advantage using a mesh network for a SON is that each node such as node <b>510</b> is directly, at least logically, connected to other nodes such as nodes <b>520</b>-<b>540</b> even though the other nodes are located in different clouds. When two nodes are directly connected, the communication between the two nodes will be easier and more robust. In addition, existing networking protocols for point-to-point connection become available to nodes that are connected in the mesh network.
0069<figref idref="DRAWINGS">FIG. 6</figref> is a logic block diagram <b>600</b> illustrating an exemplary network connected by a point-to-point mesh configuration using SON in accordance with one embodiment of the present invention. Diagram <b>600</b> includes nodes <b>510</b>-<b>540</b> and point-to-point connections <b>602</b>-<b>614</b>. Each node is directly connected to the rest of nodes within the SON in a full-mesh configuration. For example, node <b>510</b> is directly connected to node <b>530</b> via connection <b>602</b> and node <b>520</b> via connection <b>608</b>. Also, node <b>510</b> is connected to node <b>540</b> via connection <b>604</b>. Similarly, node <b>540</b> is directly connected to node <b>530</b> via connection <b>606</b> and node <b>520</b> via connection <b>614</b>. Also, node <b>540</b> is connected to node <b>510</b> via connection <b>604</b>. In one aspect, every node in the mesh network is directly connected to all other nodes in the network.
0070The exemplary aspect of the present invention includes various processing steps, which will be described below. The steps of the aspect may be embodied in machine, router, or computer executable instructions. The instructions can be used to create a general purpose or special purpose system, which is programmed with the instructions, to perform the steps of the exemplary aspect of the present invention. Alternatively, the steps of the exemplary aspect of the present invention may be performed by specific hardware components that contain hard-wired logic for performing the steps, or by any combination of programmed computer components and custom hardware components.
0071<figref idref="DRAWINGS">FIG. 7</figref> is a flowchart <b>700</b> illustrating an exemplary process of establishing SON across cloud boundaries in accordance with one embodiment of the present invention. At block <b>702</b>, a process able to launch and maintain SON is capable of receiving a first request from a dashboard managed by an orchestrator for establishing SON. SON is able to facilitate a point-to-point connection from a first node in a first cloud over a communication network. In one aspect, a dashboard managed by orchestrator interacts with the user for facilitating options or user selections before launching a VM. For example, an option selected by a first user is received via a dashboard which is facilitated by the orchestrator for launching VN.
0072At block <b>704</b>, the process is able to receive a second request for connecting to the SON from a second node in a second cloud over the communication network. In one example, a SON selection is received from a dashboard managed by the orchestrator from a second user via a node from a public cloud.
0073At block <b>706</b>, the process establishes a first connection between a first port of the first node and the second port of the second node using a network security protocol such as IPSec. After receiving a third request for connecting to the SON from a third node in a third cloud over the communication network, a second connection is established between the first port of the first node and the third node of the third cloud. A third connection is also established or created between the second node of the second cloud and the third node of the third cloud. As more requests are received for adding a cloud to the SON, a new connection is created from the new node of the new cloud to each existing node of each existing cloud to form the full-mesh. Note that IPsec is able to build a secure packet exchange tunnel at IP layer.
0074While particular embodiments of the present invention have been shown and described, it will be obvious to those of ordinary skills in the art that based upon the teachings herein, changes and modifications may be made without departing from this exemplary embodiment(s) of the present invention and its broader aspects. Therefore, the appended claims are intended to encompass within their scope all such changes and modifications as are within the true spirit and scope of this exemplary embodiment(s) of the present invention.
Contents5
9 sheets
Sheet 1 Sheet 2 Sheet 3 Sheet 4 Sheet 5 Sheet 6 Sheet 7 Sheet 8 Sheet 9
Every citation, both ways
| Document | Relation | Office | Cited during |
|---|---|---|---|
| US10565214B2 | Cited by | United States of America | Applicant |
| US2003191937A1 | Cites | United States of America | Search report |
| US2010100616A1 | Cites | United States of America | Search report |
| US2012023325A1 | Cites | United States of America | Search report |
| US2013283364A1 | Cites | United States of America | Search report |
| US2013311778A1 | Cites | United States of America | Search report |
| US2015163244A1 | Cites | United States of America | Search report |
| US2015365512A1 | Cites | United States of America | Search report |
| US7907595B2 | Cites | United States of America | Search report |
| US8908698B2 | Cites | United States of America | Search report |
| US20030191937A1 | Cites | United States of America | Search report |
| US20100100616A1 | Cites | United States of America | Search report |
| US20120023325A1 | Cites | United States of America | Search report |
| US20130283364A1 | Cites | United States of America | Search report |
| US20130311778A1 | Cites | United States of America | Search report |
| US20150163244A1 | Cites | United States of America | Search report |
| US20150365512A1 | Cites | United States of America | Search report |
| Adeyinka, Olalekan. “Analysis of IPSec VPNs performance in a multimedia environment.” Intelligent Environments, 2008 IET 4th International Conference on. IET, 2008. | Non-patent | – | Search report |
| Knight, Paul, and Chris Lewis. “Layer 2 and 3 virtual private networks: taxonomy, technology, and standardization efforts.” Communications Magazine, IEEE 42.6 (2004): 124-131. | Non-patent | – | Search report |
| Adeyinka, Olalekan. "Analysis of IPSec VPNs performance in a multimedia environment." Intelligent Environments, 2008 IET 4th International Conference on. IET, 2008. | Non-patent | – | Search report |
| Knight, Paul, and Chris Lewis. "Layer 2 and 3 virtual private networks: taxonomy, technology, and standardization efforts." Communications Magazine, IEEE 42.6 (2004): 124-131. | Non-patent | – | Search report |
6 members in 1 office; this record represents the family
Priority claims2
| Document | Office | Kind | Date |
|---|---|---|---|
| 201414562326 | United States of America | A | |
| US201414562326 | – | – | – |
Members6
| Document | Office | Kind | |
|---|---|---|---|
| US2016164914A1 | United States of America | A1 | |
| US9602544B2This record | United States of America | B2 | |
| US2017214659A1 | United States of America | A1 | |
| US10154010B2 | United States of America | B2 | |
| US2019109826A1 | United States of America | A1 | |
| US10686761B2 | United States of America | B2 |
49 transactions on the USPTO file
Allowed after 1 non-final rejection, 1 final rejection and 1 RCE.
- Non-final rejections
- 1
- Final rejections
- 1
- RCEs
- 1
- Appeals
- 0
Over time
Point at a mark for the transactionTransactions
| Event | Code | |
|---|---|---|
| Payment of Maintenance Fee, 8th Year, Large EntityM1552 | M1552 | |
| Electronic ReviewELC_RVW | ELC_RVW | |
| Email NotificationEML_NTR | EML_NTR | |
| Change in Power of Attorney (May Include Associate POA)PA.. | PA.. | |
| Payment of Maintenance Fee, 4th Year, Large EntityM1551 | M1551 | |
| Recordation of Patent Grant MailedPGM/ | PGM/ | |
| Patent Issue Date Used in PTA CalculationAllowedPTAC | PTAC | |
| Issue Notification MailedAllowedWPIR | WPIR | |
| Dispatch to FDCD1935 | D1935 | |
| Application Is Considered Ready for IssuePILS | PILS | |
| Response to Reasons for AllowanceREAS | REAS | |
| Issue Fee Payment VerifiedN084 | N084 | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Issue Fee Payment ReceivedIFEE | IFEE | |
| Mail Notice of AllowanceAllowedMN/=. | MN/=. | |
| Notice of Allowance Data Verification CompletedAllowedN/=. | N/=. | |
| Reasons for AllowanceEX.R | EX.R | |
| Examiner's Amendment CommunicationEX.A | EX.A | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Disposal for a RCE / CPA / R129AbandonedABN9 | ABN9 | |
| Request for Continued Examination (RCE)RCEX | RCEX | |
| Request for Extension of Time - GrantedXT/G | XT/G | |
| Workflow - Request for RCE - BeginBRCE | BRCE | |
| Mail Advisory Action (PTOL - 303)MCTAV | MCTAV | |
| Advisory Action (PTOL-303)CTAV | CTAV | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Final ActionA.NE | A.NE | |
| Application ready for PDX access by participating foreign officesCCRDY | CCRDY | |
| PG-Pub Issue NotificationPG-ISSUE | PG-ISSUE | |
| Mail Final Rejection (PTOL - 326)Final rejectionMCTFR | MCTFR | |
| Final RejectionFinal rejectionCTFR | CTFR | |
| Date Forwarded to ExaminerFWDX | FWDX | |
| Response after Non-Final ActionA... | A... | |
| Correspondence Address ChangeC.ADB | C.ADB | |
| Mail Non-Final RejectionNon-final rejectionMCTNF | MCTNF | |
| Non-Final RejectionNon-final rejectionCTNF | CTNF | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Case Docketed to Examiner in GAUDOCK | DOCK | |
| Application Dispatched from OIPEOIPE | OIPE | |
| Sent to Classification ContractorPGPC | PGPC | |
| FITF set to YES - revise initial settingFTFS | FTFS | |
| Application Is Now CompleteCOMP | COMP | |
| Filing ReceiptFLRCPT.O | FLRCPT.O | |
| Applicant Has Filed a Verified Statement of Small Entity Status in Compliance with 37 CFR 1.27SMAL | SMAL | |
| Cleared by OIPE CSRL194 | L194 | |
| Patent Term Adjustment - Ready for ExaminationPTA.RFE | PTA.RFE | |
| IFW Scan & PACR Auto Security ReviewSCAN | SCAN | |
| Entity status set to undiscounted (initial default setting or status change)BIG. | BIG. | |
| Initial Exam Team nnIEXX | IEXX |
10 legal events, as the office reported them to INPADOC
Over the term
Point at a mark for the eventEvents
| Event | Code | |
|---|---|---|
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Maintenance fee paymentMAFP | MAFP | |
| AssignmentAS | AS | |
| AssignmentAS | AS | |
| Information on status: patent grantGrantedPATENTED CASESTCF | STCF | |
| AssignmentAS | AS | |
| AssignmentAS | AS |
Numbers
- Publication
- 09602544
- Publication, DOCDB
- 9602544
- Publication, EPODOC
- US9602544
- Application
- 14562326
- Application, DOCDB
- 201414562326
- Application, EPODOC
- US201414562326
Titles
- English
- Methods and apparatus for providing a secure overlay network between clouds
Patent term adjustment
- Applicant delay
- −28 days
- Net adjustment
- 0 days
Classification
- CPC, 11
- H04L63/20
- H04L63/0272
- G06F9/45558
- G06F2009/45579
- G06F2009/45587
- G06F2009/45595
- H04L67/141
- H04L67/02
- H04L67/10
- H04L67/1097
- H04L63/0281
- IPC, 3
- H04L29 06
- H04L29 08
- G06F9 455
- USPC, 1
- 001001000